A Shopify merchant advertising on Google and Microsoft is running at least four tracking systems at once: Shopify's own analytics and checkout pixels, any custom pixels added through Shopify's pixel manager, Google's tags for GA4 and Google Ads, and Microsoft's UET tag. Each of them needs the visitor's consent decision delivered in its own format, and no single Shopify admin setting covers them all. Miss one and the store is either non-compliant in Europe or silently losing conversion data. This guide walks through the complete pipeline and how to wire it up with one app install.
The pipeline starts with a single interaction. The visitor makes a choice in a certified consent banner (UniConsent is an IAB TCF 2.3 registered CMP, ID 68), and the banner's behaviour is geo-targeted: EEA and UK visitors see a consent-first banner because GDPR requires opt-in, while visitors from California, Virginia, Colorado, and other US states with privacy laws see an opt-out notice, which is what those laws actually require.
That one decision then propagates in four directions. It is written to Shopify's Customer Privacy API, so Shopify's own pixels, analytics, checkout, and marketing features respect it. It updates the four Google Consent Mode v2 signals: ad_storage, ad_user_data, ad_personalization, and analytics_storage. Those signals make GA4 and Google Ads consent-aware, with Google's conversion modeling recovering aggregate insight where consent is denied. And the ad_storage decision is forwarded to Microsoft Advertising through Microsoft UET Consent Mode, for which UniConsent is certified by Microsoft.
There is no second banner and no per-platform configuration. Everything downstream derives from the one choice.
Plenty of consent apps work by blocking third-party scripts until consent arrives, and stop there. On Shopify that is not enough, because Shopify itself sets cookies and runs tracking: checkout, Shop Pay, Shopify Audiences, Shopify's own analytics, and every pixel loaded through the pixel manager sandbox. None of that is a script the app injected, so none of it is caught by script blocking.
The only way Shopify's first-party tracking becomes consent-aware is through the Customer Privacy API, Shopify's native consent interface. When the visitor's decision is registered there, Shopify propagates it to its own surfaces, including checkout on Checkout Extensibility, and pixels in the pixel manager receive the consent state before they fire. A CMP that skips this step leaves the store's own tracking non-compliant even while third-party tags are dutifully blocked, which is the worst combination: the merchant believes the store is covered precisely because a consent app is installed.
UniConsent writes to the Customer Privacy API on every consent decision. The mechanics are documented in how the Shopify Customer Privacy API works.
Since March 2024, Google requires the Consent Mode v2 signals for advertising features on EEA and UK traffic: without ad_user_data and ad_personalization, audience building and remarketing stop, and without a consent signal at all, conversion measurement degrades. With the signals in place, tags adjust behaviour instead of simply firing or not firing. When a visitor consents, GA4 and Google Ads measure normally. When a visitor declines, Google receives cookieless pings rather than nothing, and its conversion modeling fills the measurement gap at the aggregate level, which is why advertisers with a correct Consent Mode setup keep usable campaign data even at realistic European consent rates.
The practical requirement behind all of this is a Google-certified CMP sending the four signals, which is exactly what the UniConsent banner does on Shopify with no extra tagging work.
Microsoft applies the same logic to its UET tag, which powers Microsoft Advertising conversion tracking, remarketing, and Clarity session analytics. UET tags on EEA, UK, and Swiss traffic are expected to receive an explicit consent signal, and without one, conversion tracking there degrades the same way Google's does. UniConsent forwards the banner decision to UET automatically and is one of the CMPs certified by Microsoft for it; several major CMPs still publish no UET consent documentation at all, a gap our 2026 CMP comparison covers in detail.
US state privacy laws keep arriving, and they work on an opt-out model rather than GDPR's opt-in. UniConsent applies the correct regional behaviour automatically: opt-out banners for US state visitors, with IAB GPP signals carrying the state-specific consent sections that ad platforms and bidders increasingly require. The merchant configures nothing per state; the geo-targeting and the GPP string come from the same install as the European banner.
The whole pipeline takes one install. Add UniConsent CMP from the Shopify App Store; no theme code changes are required, and the app works with Online Store 2.0 themes and Checkout Extensibility alike. In the UniConsent dashboard, pick your banner style and the regions where each behaviour applies, then run the automatic cookie scan so the disclosure matches what the store actually sets. Google Consent Mode v2 and Microsoft UET signals are enabled automatically.
Before calling it done, verify: Google Tag Assistant should show the four consent signals updating when you accept or decline the banner, and the Microsoft UET Tag Helper should show the UET tag receiving its consent state. The step-by-step version with screenshots is in the Shopify CMP tutorial.
Does this work with Checkout Extensibility? Yes. Consent stored through the Customer Privacy API carries into checkout, which is the reason the API integration matters more than script blocking.
Do I need separate apps for Google and Microsoft consent? No. UniConsent is certified for both Google Consent Mode v2 and Microsoft UET Consent Mode; one banner decision updates both.
What about US state privacy laws? Handled on the same install: opt-out banners and IAB GPP signals are applied automatically based on visitor location for California, Virginia, Colorado, and the other state laws.
What does it cost to try? UniConsent's free plan covers up to 50,000 users per month, which fits most growing stores. Install the app or create an account and verify the consent signals on your own store before paying anything.
Compliant with GDPR, CCPA, COPPA, LGPD, PECR, PDPA, PIPEDA, and more.
Activate Google Consent Mode UniConsent to enhance the accuracy of your Google Analytics and Google Ads conversion data.
Set up Google Consent Mode →Commencez à rendre votre site web et votre application conformes au RGPD de l'UE, au CPRA des États-Unis, au PIPEDA de la CA, etc.
S'inscrireProcès CIPA contre NFL.com : quand l'opt-out n'arrête pas le tracking — comment rendre l'opt-out réellement efficace

Domaine CMP first-party : diffusez votre bandeau de consentement depuis votre propre domaine
UniConsent est un CMP certifié Microsoft UET et Microsoft Clarity

Droit de réclamation au titre du RGPD britannique : changements au 19 juin 2026 et ce que les organisations doivent faire

Microsoft Advertising ajoute le Vietnam comme marché à consentement obligatoire : ce que les annonceurs doivent faire avant le 30 juin 2026
Pixels de suivi et CIPA : le règlement de 5 M$ d'European Wax Center montre pourquoi votre CMP doit bloquer les tags avant le consentement
Commencez à rendre votre site web et votre application conformes au RGPD de l'UE, au CPRA des États-Unis, au PIPEDA de la CA, etc.
S'inscrire